Skip to content

CVSS base score changed

A rescore changes the score, not the flaw: someone restated this record's severity. Nothing here says the vulnerability itself changed.

60 changes · newest first · grouped by dayCSVJSONRSS

SinceClear all
ChangedSourceRows
Counted changes of "CVSS base score changed" published by INCIBE, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.Record, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Tue 28 Jul 2026· 1 record change
2026-07-28CVE-2026-12495
whole record
INCIBE
stated at publication 9.2, now states 5.3CVSS v4.0 · base scoreCriticalMediumDays to revision 1
Mon 13 Jul 2026· 1 record change
2026-07-13CVE-2026-12257
whole record
INCIBE
stated at publication 5.1, now states 9.3CVSS v4.0 · base scoreMediumCriticalDays to revision 0
Mon 20 Apr 2026· 2 record changes
2026-04-20
whole record
INCIBE
stated at publication 9.1, now states 4.7CVSS v3.1 · base scoreCriticalMediumDays to revision 872
2026-04-20CVE-2023-5965same vendor as the line abovesame change as the line aboveDays to revision 872
2026-04-20CVE-2023-5966same vendor as the line abovesame change as the line aboveDays to revision 872
Thu 26 Mar 2026· 1 record change
2026-03-26CVE-2025-41368
whole record
INCIBE
stated at publication 8.5, now states 8.7CVSS v4.0 · base scoreHighHighDays to revision 0
Thu 2 Oct 2025· 6 record changes
2025-10-02
whole record
INCIBE
stated at publication 6.9, now states 5.1CVSS v4.0 · base scoreMediumMediumDays to revision 0
2025-10-02CVE-2025-59750same vendor as the line abovesame change as the line aboveDays to revision 0
2025-10-02CVE-2025-59751same vendor as the line abovesame change as the line aboveDays to revision 0
2025-10-02CVE-2025-59752same vendor as the line abovesame change as the line aboveDays to revision 0
2025-10-02CVE-2025-59753same vendor as the line abovesame change as the line aboveDays to revision 0
2025-10-02CVE-2025-59754same vendor as the line abovesame change as the line aboveDays to revision 0
2025-10-02CVE-2025-59756same vendor as the line abovesame change as the line aboveDays to revision 0
Thu 11 Sep 2025· 2 record changes
2025-09-11CVE-2025-41376
whole record
INCIBE
stated at publication 8.7, now states 5.1CVSS v4.0 · base scoreHighMediumDays to revision 41
2025-09-11CVE-2025-41375
whole record
INCIBE
stated at publication 8.7, now states 9.3CVSS v4.0 · base scoreHighCriticalDays to revision 41
Fri 1 Aug 2025· 1 record change
2025-08-01CVE-2025-41377
whole record
INCIBE
stated at publication 9.3, now states 8.7CVSS v4.0 · base scoreCriticalHighDays to revision 70
Fri 28 Mar 2025· 1 record change
2025-03-28CVE-2025-2908
whole record
INCIBE
stated at publication 6.9, now states 8.5CVSS v4.0 · base scoreMediumHighDays to revision 0
Wed 13 Mar 2024· 1 record change
2024-03-13CVE-2024-2414
whole record
INCIBE
stated at publication 7.8, now states 8.8CVSS v3.1 · base scoreHighHighDays to revision 0
Thu 15 Feb 2024· 42 record changes
2024-02-152 commits
whole record
INCIBE
stated at publication 7.1, now states 8.2CVSS v3.1 · base scoreHighHighBranches and original-value intervals are stated on each row.Days to revision 13 to 21
2024-02-15CVE-2024-23868same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23869same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23870same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23871same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23872same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23873same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23874same vendor as the line abovesame change as the line aboveDays to revision 20
2024-02-15CVE-2024-23875same vendor as the line abovesame change as the line aboveDays to revision 20
34 more rows in this change are not listed here. Open all 42 rows
Tue 16 Jan 2024· 1 record change
2024-01-16CVE-2024-0581
whole record
INCIBE
stated at publication 7.5, now states 4.0CVSS v3.1 · base scoreHighMediumDays to revision 0
Tue 19 Dec 2023· 1 record change
2023-12-19CVE-2023-6913
whole record
INCIBE
stated at publication 7.2, now states 8.1CVSS v3.1 · base scoreHighHighDays to revision 0

This kind is counted once per CVE record, so changes and records are the same number here. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
3,898 records with a counted edit in the 52 weeks to 7 Sep 2026 · snapshot built 03:47 UTC · scroll for earlierfewermore

Data sources and quality

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Check my CVEs against these changes →